6.8
CVSSv2

CVE-2008-2841

Published: 24/06/2008 Updated: 23/07/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Argument injection vulnerability in XChat 2.8.7b and previous versions on Windows, when Internet Explorer is used, allows remote malicious users to execute arbitrary commands via the --command parameter in an ircs:// URI.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft internet_explorer

xchat xchat

Exploits

################################################################################################################## # # Xchat <= 287b Remote Code Execution (tested on Windows XP SP1+SP2+SP3, IE6 & IE7 fully patched) # Vendor : xchatorg/ # Affected Os : Windows * # Risk : critical # # This bug is related to the URI Handler vulnerabil ...